cd /news/ai-safety/how-agents-supercharged-the-hacker-p… · home topics ai-safety article
[ARTICLE · art-123335] src=thedeepview.com ↗ pub= topic=ai-safety verified=true sentiment=↓ negative

How agents supercharged the hacker playbook

Google's Threat Intelligence Group's third-quarter report reveals that AI-enabled cyberattacks have evolved from assistance to automation, with adversaries deploying multi-agent frameworks to autonomously carry out attacks, including a mass-credential harvesting attack completed in under six hours. The report highlights that human-in-the-loop latency has dramatically decreased, and threat actors are using autonomous AI to research vulnerabilities, scan infrastructure, and perform exploits, while also targeting proprietary AI IP and using AI across the attack lifecycle.

read2 min views4 publishedSep 8, 2026
How agents supercharged the hacker playbook
Image: Thedeepview (auto-discovered)

Agents have turned AI from a tool into a digital coworker. Now, they're doing the same thing for hackers.

On Tuesday, Google's Threat Intelligence Group released its third-quarter threat tracking report, revealing that AI-enabled cyberattacks have evolved from assistance to automation as agents become a growing part of the process. The report finds that "human-in-the-loop latency" has dramatically decreased, cutting the time it takes to carry out and defend against cyberattacks.

According to the research, Google's threat team observed multiple instances of adversaries deploying multi-agent frameworks and autonomously carrying out parts of attacks, including scanning pipelines and harvesting credentials. In one instance, threat actors compromised a cloud, then planned, built and executed a mass-credential harvesting attack in just under six hours using agents.

The attack marks a shift from "passive, endpoint-focused infostealers to offensive agentic harvesting," the report notes, as threat actors leverage autonomous AI to research vulnerabilities, scan infrastructure and perform exploits.

"Like everyone else, we’re concerned about the vulnerability problem, but AI is being applied to several other areas, and it will be especially challenging as it is applied agentically, creating a scaled, faster adversary," John Hultquist, chief analyst of the Google Threat Intelligence Group, said in a statement.

Agents aside, the report points to a number of concerning trends:

  • AI-coding tools and open-source software, while accelerating software development cycles, have also increased operational risks by widening the attack surface.
  • Adversaries are also targeting proprietary AI IP, including code, prompts, research and the models themselves.
  • AI is being used across the attack lifecycle, including targeting reconnaissance, social engineering, custom malware obfuscation and scaling information operation campaigns.
  • Bad actors are also stealing developer credentials, purchasing compromised AI accounts and breaking into cloud infrastructure to get around AI access costs.

Our Deeper View #

Google's threat report cements into reality the thing that has the AI industry on edge in the wake of OpenAI's accidental breach of Hugging Face: autonomous, agent-driven cyberattacks are here. Though many fear what agents could do if they go rogue, Google's report paints a potentially more nerve-racking picture: bad actors are harnessing powerful AI tools to systematically do damage. This means that the approach to fighting these attacks has to be two-pronged. The obvious one is fighting fire with fire. Using AI agents to automatically detect and deflect cyberattacks is no longer novel, but a necessity. This, however, could be more effective when done in tandem with more creative means of defense, such as Cloudflare's recently announced tech that stalls cyberattacks by making attacks more expensive. What cyber defenders may need most is confidence that they have the tools and partners to defend against AI-enabled attacks, which is what CrowdStrike emphasized at its annual event last week.

── more in #ai-safety 4 stories · sorted by recency
── more on @google threat intelligence group 3 stories trending now
sponsored brought to you by zahid.host 4,200+ EU-deployed projects
reading about agents? ship yours in a single git push.

Run your AI side-project on zahid.host

EU-based hosting, git-push deploys, automatic HTTPS, no cold starts. Free tier with a custom domain — perfect for shipping the agent you just read about.

$git push zahid main
Live at https://your-agent.zahid.host
Get free account → Pricing
from €0/mo · no card required
LIVE [news/how-agents-superchar…] indexed:0 read:2min 2026-09-08 ·